Directive NIS2 European Union
Cart 0
Art. 20

Management body


The governing organ of an entity, which must approve cybersecurity risk-management measures, oversee their implementation and follow training.

Article 20 is what moved NIS2 into boardrooms. Member states must ensure management bodies can be held liable for infringements, and article 32(6) allows a competent authority to temporarily prohibit a named individual from exercising managerial functions in an essential entity.

Related terms

Full glossary →

Cart 0